Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra software in the parameter 'filter' in the endpoint 'indexsearch' allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects DInGO dLibra software in versions from 6.0 before 6.3.20.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Poznan Supercomputing And Networking Center
Poznan Supercomputing And Networking Center dingo Dlibra |
|
CPEs | cpe:2.3:a:poznan_supercomputing_and_networking_center:dingo_dlibra:*:*:*:*:*:*:*:* | |
Vendors & Products |
Poznan Supercomputing And Networking Center
Poznan Supercomputing And Networking Center dingo Dlibra |
|
Metrics |
ssvc
|
Thu, 14 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra software in the parameter 'filter' in the endpoint 'indexsearch' allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects DInGO dLibra software in versions from 6.0 before 6.3.20. | |
Title | Reflected XSS in DInGO dLibra | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: CERT-PL
Published: 2024-11-14T15:07:50.313Z
Updated: 2024-11-14T16:06:24.925Z
Reserved: 2024-07-26T06:14:05.930Z
Link: CVE-2024-7124
Vulnrichment
Updated: 2024-11-14T16:06:09.419Z
NVD
Status : Received
Published: 2024-11-14T15:15:09.177
Modified: 2024-11-14T15:15:09.177
Link: CVE-2024-7124
Redhat
No data.